Tamga Network

Join

Join Tamga Network

Tamga Network is a trust network: institutions issue credentials, verifiers check them, wallets carry them, and signed trust lists say who is who. There are three ways in.

Data stays with the institution

The network does not access an institution's database and does not store people's data. At issuance the details are read through an endpoint the institution controls, signed with the institution's own key and sent to the person's phone.

Three ways to join

issuers and verifiers

Institutions

Universities, hospitals, chambers, public bodies, companies and event organisers issue credentials; employers, websites and gates verify them.

  • registration data and an X.509 certificate
  • an entry in the signed trust list
  • hosted issuance or your own server (open-source packages)

EU-compatible wallets

Wallet providers

Any wallet that follows the network's wallet rules can carry Tamga credentials. Tamga Wallet is the network's first wallet, not the only one.

  • registration as a wallet provider in the trust list
  • wallet instance and key attestations
  • conformance tests against the reference verifier

federation

States and national lists

A state or trust-list operator keeps its own list. The network reads it with a pinned signer and an agreed scope; it does not copy or overrule it.

  • an external list in the ETSI format (TS 119 602)
  • a pinned signing certificate and a defined scope
  • approval through the network's governance

Which institutions

Education
student credential, diploma, certificates
Health
licence to practise, chamber membership, employment credential (in preparation)
Public bodies
credentials from an authentic source, on behalf of the state
Companies
employee and authorisation credentials, building access
Events
tickets bound to a person, single-use at the gate

What joining changes

No confirmation requests

verifiers check the credential themselves; nobody needs to call or write to the institution.

No forgeries

without the institution's signature and its entry in the signed trust list, no valid credential can exist.

Control

revoke or suspend at once; issuance statistics in the Institution Console, never personal data.

Data minimisation

people share only what is asked; the institution never learns to whom a credential was shown.

European standards

SD-JWT VC, OpenID4VCI / OpenID4VP, X.509 and signed trust lists — the EU wallet's building blocks.

Open source

the network's packages are Apache-2.0; issuance can also run on the institution's own servers.

What an institution needs

Registration data

  • legal name and display name
  • official identifier (tax number, trade register number)
  • postal address, website, institutional contact
  • data protection authority; public body or not
  • privacy policy link (shown in the wallet)

Legal

  • participation agreement
  • data processing agreement when the hosted service is used: the institution is the controller
  • updated privacy notice for the people it issues to
  • proof that it is entitled to issue this credential

Technical

  • a signing key generated in its own key vault (KMS / HSM); only a certificate request (CSR) is sent
  • a lookup endpoint in front of its records, following the OpenAPI contract, and/or API calls
  • a revocation process (API or Institution Console)
  • technical, data-protection and security contacts

How joining works

  1. 1 · Scope

    which credentials, which pilot group

  2. 2 · Credential type

    choose from the public catalogue or design a new type together

  3. 3 · Legal

    agreements and privacy notice

  4. 4 · Registration

    registration data, certificate, entry in the trust list

  5. 5 · Integration

    lookup endpoint and/or API, tested end to end in the sandbox

  6. 6 · Pilot, then live

    a small group first, then everyone

Verifying instead of issuing?

Employers, websites and gates join as registered verifiers: for each use they register which credential and fields they request, the purpose and a privacy policy. The wallet warns people when a verifier asks for more than it registered.

Apply

Write to us with your organisation's name and how you want to join: issuing, verifying, as a wallet provider or with a national list. We reply with the full requirements guide.

partners@tamga.networkStep-by-step guide: Joining as an institution (developer docs) →